Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 20% | — | Vmware Carbon Black APP Control | 23/3/2022 | 17/6/2026 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute… | |
| Modificada | Media (6.5) | 0.95% | — | Jenkins Vmware Vrealize Codestream | 15/3/2022 | 17/6/2026 | Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Media (5.5) | 4.8% | — | Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+2 | 4/3/2022 | 17/6/2026 | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates. | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud GatewayOracle Commerce Guided SearchOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Console+6 | 3/3/2022 | 17/6/2026 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host. | |
| Modificada | Media (6.7) | 1.2% | — | Vmware Tools | 3/3/2022 | 17/6/2026 | VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an… | |
| Modificada | Media (5.4) | 0.46% | — | Vmware Workspace ONE Boxer | 2/3/2022 | 17/6/2026 | VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization and validation, in VMware Workspace ONE Boxer calendar event descriptions, a malicious actor can inject script tags to execute arbitrary script within a user's window. | |
| Modificada | Alta (7.8) | 0.35% | — | Vmware Cloud FoundationVmware NSX Data Center | 16/2/2022 | 17/6/2026 | VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root. | |
| Modificada | Alta (7.5) | 2.3% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware FusionVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files. | |
| Modificada | Alta (7.8) | 0.30% | — | Vmware Cloud FoundationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user. | |
| Modificada | Media (6.7) | 0.57% | — | Vmware Cloud FoundationVmware FusionVmware WorkstationVmware Esxi | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Media (6.7) | 0.73% | — | Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+1 | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Media (4.9) | 0.78% | — | Vmware Cloud Foundation | 4/2/2022 | 17/6/2026 | VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files. | |
| Modificada | Media (6.5) | 0.36% | — | Vmware WorkstationVmware Horizon | 28/1/2022 | 17/6/2026 | VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a… | |
| Modificada | Media (4.3) | 0.85% | — | Vmware Spring FrameworkOracle Communications Cloud Native Core ConsoleOracle Communications Cloud Native Core Service Communication Proxy | 10/1/2022 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring… | |
| Modificada | Alta (7.8) | 4.7% | — | Vmware Cloud FoundationVmware WorkstationVmware FusionVmware Esxi | 4/1/2022 | 17/6/2026 | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this… | |
| Modificada | Alta (8.8) | 1.1% | — | Vmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify. | |
| Modificada | Alta (7.5) | 1.6% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Workspace ONE UEM Console | 17/12/2021 | 1/10/2026 | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to… | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Advanced Message Queuing Protocol | 30/11/2021 | 17/6/2026 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message | |
| Modificada | Alta (7.5) | 1.7% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+21 | 24/11/2021 | 17/6/2026 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings… | |
| Modificada | Crítica (9.8) | 3.3% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+22 | 24/11/2021 | 17/6/2026 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client… | |
| Modificada | Crítica (9.8) | 1.7% | — | Vmware Vcenter Server | 24/11/2021 | 17/6/2026 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | |
| Modificada | Alta (7.5) | 4.7% | 💥 PoC | Vmware Cloud FoundationVmware Vcenter Server | 24/11/2021 | 17/6/2026 | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information. | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | Vmware Spring Cloud Netflix | 19/11/2021 | 17/6/2026 | Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following… |